Hardware wallet maker Coinkite is facing the fallout from what is shaping up to be the largest hardware wallet breach on record, after a vulnerability in Coldcard firmware allowed attackers to drain more than 1,778 Bitcoin, worth roughly $112M at prevailing prices, from over 5,000 addresses.

The theft began on July 30, 2026. Within 41 minutes, attackers had swept more than 1,000 BTC from over 1,000 addresses. As of mid-August 2026, approximately 1,531 BTC remained sitting untouched in wallets controlled by the attackers.

A bug that was hiding in plain sight since 2021

The root cause traces back to a firmware update Coinkite shipped in March 2021, version 4.0.1. That update introduced a flaw in the seed phrase generation process, the step where a hardware wallet creates the master key that controls all funds stored on it.

Instead of pulling randomness from the device’s dedicated hardware random number generator, the flawed code rerouted that process to a software-based pseudorandom number generator. The difference matters enormously: a software PRNG is far more predictable than its hardware counterpart, and predictable randomness in cryptography is essentially an open door.